Get a Demo
Under Attack?
Red-agent-deep-dive

Building Autonomous Cloud & AI Security

How Upwind’s Agentic Pack uses NVIDIA Nemotron 3 Super and NVIDIA garak agent breaker probe to continuously validate cloud posture, attack surfaces, and AI applications.

By: Avital Harel, Alon Saban, Yuval Elarat (Upwind). Eliya Cohen, Shiri Hochhauser, Orel Hazai (NVIDIA)

Executive Summary

AI-generated code, autonomous agents, MCP servers, and cloud-native architectures are transforming how software is built and reshaping the enterprise attack surface in the process. Upwind is building new tools for defenders as a member of the Open Secure AI Alliance with NVIDIA and other organizations.

Modern attackers rarely exploit a single vulnerability. Instead, they chain together misconfigurations, APIs, over-permissioned identities, and AI-powered applications to reach high-value cloud resources.

For defenders, the challenge isn’t finding issues anymore. It is determining which findings represent exploitable business risk.

 The Upwind Agentic Pack offers specialized AI agents that investigate, validate, and remediate findings using real production context. Each agent is purpose-built for a specific part of the security lifecycle, sharing the same runtime intelligence and environmental understanding.

At the center of the validation workflow is Red, the validation agent.

Offensive-Agent-Full

The Red Agent continuously validates cloud posture, external attack surfaces, and AI-powered applications, including LLMs, MCP servers, and autonomous agents, to help determine whether a finding is real and exploitable. It reasons through attack paths, validates exploitability, measures blast radius, and provides evidence-based prioritization for remediation.

To strengthen these capabilities, the Red Agent incorporates NVIDIA AI technologies at key stages of the assessment process.

The NVIDIA Nemotron 3 Super (NVIDIA-Nemotron-3-Super-120B-A12B) open model is the reasoning engine that analyzes cloud posture findings and attack surface observations, helping the Red Agent determine which misconfigurations warrant deeper validation, distinguish theoretical exposures from exploitable risks, and continuously help prioritize investigations based on evolving evidence.

When AI-powered applications, LLMs, or agentic workflows are found by the Red Agent, it uses the agent breaker probe within garak, NVIDIA’s open-source AI red-teaming tool, to evaluate their security posture against AI-specific threats such as prompt injection, indirect prompt manipulation, unsafe tool usage, unsafe agent behavior, and other emerging attack techniques.

Together, they are capable of continuously validating both traditional cloud infrastructure and the growing AI attack surface.

red-1

Cloud Security Has Become a Reasoning Problem

Traditional cloud security was built around discovery. Find the vulnerability, flag the misconfiguration, and prioritize remediation. That was suitable when cloud environments changed relatively slowly.

Today’s environments are different.

Cloud infrastructure changes continuously, and AI accelerates this further, generating code, spinning up APIs, and deploying autonomous agents that touch production systems directly.

As a result, security teams are inundated with findings spanning cloud posture, identities, APIs, runtime behavior, and AI applications. Visibility isn’t the problem anymore.

The real challenge is determining which of those findings actually represent exploitable business risk and prioritize patching.

Static scanning and predefined rules can’t answer that. It requires reasoning over relationships between infrastructure, identities, applications, and AI systems as the environment evolves. Cloud and AI security have become a reasoning problem.

Autonomous Security with the Upwind Agentic Pack

Different security workflows require different expertise. No single model does it all. The Agentic Pack is a collection of specialized agents sharing the same runtime intelligence and environmental context for the full security lifecycle.

The Red Agent sits at the center of validation. It can assess cloud misconfigurations, attack surfaces, APIs, identities, runtime behavior, and AI applications to determine what’s actually exploitable, enriching every assessment with Upwind’s runtime intelligence of running workloads, network communications, identities, and application topology.  With the Red Agent, we can assess not just whether a risk exists, but also whether it is reachable, its blast radius, and prioritization.

red-2

Autonomous Reasoning Powered by NVIDIA Nemotron

Evidence alone doesn’t tell you if you’re at risk. A critical-looking misconfiguration might be isolated from production; several low-risk findings might combine into a real attack path. The Red Agent continuously builds a security graph from runtime data. It uses NVIDIA Nemotron 3 Super as its reasoning engine to assess where deeper validation creates the most value, to help guide the investigation toward the exposures with the most risk.

Security teams can obtain validated, evidence-based agent assessments around what was found, possible risk, how it may be exploited, and suggestions on next steps.

Extending Validation to AI Applications with garak

When the Red Agent discovers an agent, it automatically triggers an assessment via the garak-agent-breaker probe, testing for prompt injection, indirect prompt manipulation, unsafe tool usage, excessive agent permissions, and other AI-specific threats.

These findings are correlated with cloud posture, identities, and attack-path analysis giving teams a more holistic understanding of the risk.

From Findings to Security Posture

By combining Upwind’s runtime intelligence with autonomous reasoning from NVIDIA Nemotron 3 Super and AI security validation through garak, the Red Agent transforms isolated observations into evidence-based validation.

Rather than prioritizing findings based solely on severity scores, organizations can also use evidence-based validation to assess risk and which remediation actions may have the greatest security impact.

Building the Next Generation of Autonomous Cloud & AI Security

The future of cloud security will not be defined by larger vulnerability databases or additional scanning rules. It will be defined by autonomous security systems that continuously observe, reason, validate, and improve an organization’s security posture as cloud environments evolve.

This is the vision behind our research and collaboration with NVIDIA.

By combining Upwind’s runtime-first security platform and Agentic Pack with NVIDIA open models and AI technologies, Upwind is building an improved approach to cloud and AI security. One that continuously validates risk instead of simply reporting findings. Runtime intelligence provides the real-world context. Specialized AI agents investigate and validate exposures. NVIDIA Nemotron powers the reasoning that guides each investigation, while garak extends validation to AI applications, LLMs, MCP servers, and autonomous agents.

Using these technologies together, we can build a continuous security validation workflow that helps organizations distinguish theoretical exposures from exploitable risks, understand attack paths, measure business impact, and prioritize remediation based on evidence.

As enterprises continue adopting AI-generated applications, autonomous agents, and increasingly dynamic cloud architectures, security must evolve alongside them. Defenders need more than visibility. They need to scale the expertise of their best people. That means autonomous systems capable of continuously validating cloud posture, AI security, and emerging attack surfaces as environments change.

We believe this is the future of cloud security.

Upwind, an NVIDIA Inception member, is helping define the next generation of autonomous cloud and AI security, where continuous security validation becomes the foundation for protecting modern applications, AI workloads, and the cloud environments we depend on.

Contents

Further Reading

Agent Scanner

Announcing the Upwind AI Context Scanner – Securing AI Agents’ Instructions, Skills and Model Context

AI agents are spreading across enterprise operations, from local coding tools on employee endpoints, to agents operating infrastructure or processing sensitive customer data, to fully autonomous cloud workflows. Agents operate with human credentials and gain real system access, and introduce a brand-new attack surface. To secure an AI agent, you have to look deep in…
AI-DR-Hero (1)

Upwind AI DR is Generally Available: metaCatch Compromised AI Agents in Real Time

We're excited to announce that Upwind AI DR (AI Detection & Response) is now generally available. AI DR gives security teams real-time detection and response for the AI agents running in production, not by bolting on a new sensor, but by extending the runtime intelligence Upwind already has. The Upwind Cloud & AI Security Platform…
Focus-Mode

Focus Mode for AI Security: A Dedicated Workspace for Identifying and Securing Your AI Stack 

When we launched Focus Mode, we built it around the way security teams actually work: Vulnerability Management, Cloud Security Posture, Attack Surface Management, Threat Detection & Response, Administration. Each one strips away everything unrelated to the job at hand. AI Security is the next domain in the Focus Mode lineup, and it's built for a…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS